Skip to content

Commit a6e8c82

Browse files
authored
Merge pull request #1143 from nassima17/cti/add-uat9921-voidlink
new: [threat-actor] Add UAT-9921 (VoidLink operator China Nexus)
2 parents db4cd46 + 27fb6fb commit a6e8c82

2 files changed

Lines changed: 17 additions & 1 deletion

File tree

README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -703,7 +703,7 @@ Category: *tea-matrix* - source: ** - total: *7* elements
703703

704704
[Threat Actor](https://www.misp-galaxy.org/threat-actor) - Known or estimated adversary groups targeting organizations and employees. Adversary groups are regularly confused with their initial operation or campaign. threat-actor-classification meta can be used to clarify the understanding of the threat-actor if also considered as operation, campaign or activity group.
705705

706-
Category: *actor* - source: *MISP Project* - total: *940* elements
706+
Category: *actor* - source: *MISP Project* - total: *941* elements
707707

708708
[[HTML](https://www.misp-galaxy.org/threat-actor)] - [[JSON](https://github.com/MISP/misp-galaxy/blob/main/clusters/threat-actor.json)]
709709

clusters/threat-actor.json

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19796,6 +19796,22 @@
1979619796
},
1979719797
"uuid": "2462885d-f49e-4731-a163-da704e50aca7",
1979819798
"value": "CL-STA-1009"
19799+
},
19800+
{
19801+
"description": "UAT-9921 is a China-nexus threat actor active since 2019, tracked by Cisco Talos. In 2026, they were observed deploying 'VoidLink', a sophisticated modular framework primarily targeting Linux systems (IoT, Critical Infrastructure). Unique characteristics include the use of AI-enabled IDEs for rapid development (ZigLang implant, GoLang backend), P2P mesh networking for C2, and advanced persistence via eBPF rootkits. They target Technology and Financial sectors exploiting Java serialization vulnerabilities (Apache Dubbo).",
19802+
"meta": {
19803+
"country": "CN",
19804+
"refs": [
19805+
"https://blog.talosintelligence.com/voidlink/",
19806+
"https://isovalent.com/blog/post/voidlink-cloud-malware-detection/"
19807+
],
19808+
"synonyms": [
19809+
"UAT-9921",
19810+
"VoidLink Operator"
19811+
]
19812+
},
19813+
"uuid": "d2c1b9a8-e3f4-4123-a567-b8c9d0e1f2a3",
19814+
"value": "UAT-9921"
1979919815
}
1980019816
],
1980119817
"version": 337

0 commit comments

Comments
 (0)